CVE-2006-4602
Tikiwiki Cms/groupware - Unrestricted File Upload
Title source: ruleDescription
Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory.
Exploits (3)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/16885
metasploit
WORKING POC
EXCELLENT
rubypocunix
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/unix/webapp/tikiwiki_jhot_exec.rb
References (9)
Scores
EPSS
0.8336
EPSS Percentile
99.3%
Details
Status
published
Products (1)
tiki/tikiwiki_cms\/groupware
1.9.4
Published
Sep 07, 2006
Tracked Since
Feb 18, 2026